# Incident runbook

For each section, state the evidence and name unresolved assumptions. Use synthetic or appropriately authorized information.

## Service, environment, owner, escalation contact

[Write your evidence and decision here.]

## Symptoms and user impact

[Write your evidence and decision here.]

## Safe diagnostic commands and dashboards

[Write your evidence and decision here.]

## Containment: disable writes or affected path

[Write your evidence and decision here.]

## Evidence and timeline preservation

[Write your evidence and decision here.]

## Dependency, data, identity, and recent-change checks

[Write your evidence and decision here.]

## Recovery or rollback procedure

[Write your evidence and decision here.]

## Validation before declaring recovery

[Write your evidence and decision here.]

## Stakeholder update template

[Write your evidence and decision here.]

## Postmortem actions, owners, and due dates

[Write your evidence and decision here.]
